[VulnDiscuss] RE: Re: [VulnDiscuss] eEye - SQL Sapphire Worm Analysis

"Marc Maiffret" <[email protected]>
Newsgroups gmane.comp.security.vulnerabilities.watch.general,gmane.comp.security.bugtraq
Message-ID <[email protected]>
Actually I must have missed where in
"http://www.nextgenss.com/advisories/mssql-udp.txt" did you disassemble the
current worm going on? Ahh right we must have "recited" the worm disassembly
from somewhere else hidden on your website. Right.

There is a worm out there, it is affecting people, people need to know what
is going on. Yah its a 6 month old vulnerability... great that shows people
are not paying attention (Just like Codered). Even more of a reason to do
the research to see what is going on and try to educate people further. But
no your right never mind... its an old flaw people should have known
better... we should all have not done any analysis of the worm because yah
its using an old flaw that you found. Great.

ISS, eEye, Symantec.... the analysis was for getting the cool name. I know
ours was... Sapphire and Tonic rules. I mean we couldn't possibly have
wanted to do research to answer the million and one emails that have been
flying across mailing lists the last two days with people wondering what in
the hell is going on with their networks and SQL servers. You know it IS all
for the name. Maybe that makes it worthwhile to me to have been up for over
40 hours now and finishing up a free scanning tool to give to people to help
them out. Yes, its all for the name, _seriously_...

Oh and Symantec's/Securityfocus's "Voyager Alpha Force" "worm" is an IRC bot
controlled system... which has nothing to do with this current worm. But I
am sure you knew that in your quick haste to get in on things.

No worries though... next time we are trying to get an alert out to the
community, to let them know what's going on, well make sure to stop and ask
the person who found the flaw what they want to name to it. Obviously its
not good enough to credit their research and link back to them from our
website.

Oh... you already missed the wagon. But thanks for the zero substance email,
after the fact, stating the pointlessly obvious.

Signed,
Marc Maiffret
Chief Hacking Officer
eEye Digital Security
T.949.349.9062
F.949.349.9538
http://eEye.com/Retina - Network Security Scanner
http://eEye.com/Iris - Network Traffic Analyzer
http://eEye.com/SecureIIS - Stop known and unknown IIS vulnerabilities

| -----Original Message-----
| From: Mark Litchfield [mailto:[email protected]]
| Sent: Saturday, January 25, 2003 8:01 PM
| To: Steve W. Manzuik; [email protected]
| Cc: [email protected]; [email protected]
| Subject: [VulnWatch] Re: [VulnDiscuss] eEye - SQL Sapphire Worm Analysis
|
|
| I find it very interesting that Eeye and ISS Xforce seem to be more
| interested in giving the worm a name and basically reciting what
| was already
| posted in David's advisory
| http://www.nextgenss.com/advisories/mssql-udp.txt
| on the 25th July 2002,    media attention I wonder ;) and with Security
| Focus naming it Voyager Alpha Force.
|
| Not to miss the wagon:
|
| Based on the fact that it affects SQL servers, and interestingly enough 6
| months to the day, that remain unpatched, and would have been protected,
| before everyone goes and starts to blame MS, I've scraped the barrel to
| produce the following,
|
| Regards Mark
|
|
| Security Quite Late worm  J
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.